Over 16,000 Supabase databases expose PII, passwords, auth tokens
16,000+ exposed Supabase databases, PII in more than half of them, and not a single vendor CVE in sight. UpGuard scanned ~300,000 domains and found things like a Canadian immigration service leaking 884 plaintext passwords. The cause is row-level security nobody enabled and public keys used where they shouldn’t be. Worth noting: 60%+ of new Supabase databases now come from AI-assisted development.